We propose a methodology for falsifying safety properties in robotic vehicle systems through property-guided reduction and surrogate execution. By isolating only the control logic and physical dynamics relevant to a given specification, we construct lightweight surrogate models that preserve property-relevant behaviors while eliminating unrelated system complexity. This enables scalable falsification via trace analysis and temporal logic oracles. We demonstrate the approach on a drone control system containing a known safety flaw. The surrogate replicates failure conditions at a fraction of the simulation cost, and a property-guided fuzzer efficiently discovers semantic violations. Our results suggest that controller reduction, when coupled with logic-aware test generation, provides a practical and scalable path toward semantic verification of cyber-physical systems.
Cyber-physical systems (CPS) increasingly face security threats that can disrupt critical infrastructure operations. The SPHERE CPS enclave is a modular, remotely accessible industrial control system (ICS) testbed designed to support security experimentation on programmable logic controllers (PLCs), industrial networks, and digital twin simulations. It enables researchers to investigate cyber-physical attacks, anomaly detection, and intrusion resilience strategies. Unlike general cybersecurity testbeds, SPHERE's CPS enclave provides a configurable, realistic environment for studying adversarial scenarios that bridge cyber and physical domains. The infrastructure offers controlled, reproducible experiments with customizable network topologies and hardware-in-the-loop validation. This poster presents the design philosophy, community-driven experimental goals, and deployment considerations of the SPHERE CPS enclave, demonstrating its potential for advancing CPS security research.
The global greening trend, marked by significant increases in vegetation cover across ecoregions, has attracted widespread attention. However, even robust traditional methods, like the nonparametric Mann-Kendall test, often overlook crucial factors such as serial correlation, spatial autocorrelation, and multiple testing, particularly in spatially gridded data. This oversight can lead to inflated significance of detected spatiotemporal trends. To address these limitations, this research introduces the True Significant Trends (TST) workflow, which enhances the conventional approach by incorporating pre-whitening to control for serial correlation, Theil-Sen (TS) slope for robust trend estimation, the Contextual Mann-Kendall (CMK) test to account for spatial and cross-correlation, and the adaptive False Discovery Rate (FDR) correction. Using AVHRR NDVI data over 42 years (1982-2023), we found that conventional workflow identified up to 50.96% of the Earth's terrestrial land surface as experiencing statistically significant vegetation trends. In contrast, the TST workflow reduced this to 38.16%, effectively filtering out spurious trends and providing a more accurate assessment. Among these significant trends identified using the TST workflow, 76.07% indicated greening, while 23.93% indicated browning. Notably, considering areas (pixels) with NDVI values above 0.15, greening accounted for 85.43% of the significant trends, with browning making up the remaining 14.57%. These findings strongly validate the ongoing global greening of vegetation. They also suggest that incorporating more robust analytical methods, such as the True Significant Trends (TST) approach, could significantly improve the accuracy and reliability of spatiotemporal trend analyses.
While IoT sensors in physical spaces have provided utility and comfort in our lives, their instrumentation in private and personal spaces has led to growing concerns regarding privacy. The existing notion behind IoT privacy is that the sensors whose data can easily be understood and interpreted by humans (such as cameras) are more privacy-invasive than sensors that are not human-understandable, such as RF (radio-frequency) sensors. However, given recent advancements in machine learning, we can not only make sensitive inferences on RF data but also translate between modalities. Thus, the existing notions of privacy for IoT sensors need to be revisited. In this paper, our goal is to understand what factors affect the privacy notions of a non-expert user (someone who is not well-versed in privacy concepts). To this regard, we conduct an online study of 162 participants from the USA to find out what factors affect the privacy perception of a user regarding an RF-based device or a sensor. Our findings show that a user's perception of privacy not only depends upon the data collected by the sensor but also on the inferences that can be made on that data, familiarity with the device and its form factor as well as the control a user has over the device design and its data policies. When the data collected by the sensor is not human-interpretable, it is the inferences that can be made on the data and not the data itself that users care about when making informed decisions regarding device privacy.
Autonomous robots, autonomous vehicles, and humans wearing mixed-reality headsets require accurate and reliable tracking services for safety-critical applications in dynamically changing real-world environments. However, the existing tracking approaches, such as Simultaneous Localization and Mapping (SLAM), do not adapt well to environmental changes and boundary conditions despite extensive manual tuning. On the other hand, while deep learning-based approaches can better adapt to environmental changes, they typically demand substantial data for training and often lack flexibility in adapting to new domains. To solve this problem, we propose leveraging the neurosymbolic program synthesis approach to construct adaptable SLAM pipelines that integrate the domain knowledge from traditional SLAM approaches while leveraging data to learn complex relationships. While the approach can synthesize end-to-end SLAM pipelines, we focus on synthesizing the feature extraction module. We first devise a domain-specific language (DSL) that can encapsulate domain knowledge on the essential attributes for feature extraction and the real-world performance of various feature extractors. Our neurosymbolic architecture then undertakes adaptive feature extraction, optimizing parameters via learning while employing symbolic reasoning to select the most suitable feature extractor. Our evaluations demonstrate that our approach, neurosymbolic Feature EXtraction (nFEX), yields higher-quality features. It also reduces the pose error observed for the state-of-the-art baseline feature extractors ORB and SIFT by up to 90% and up to 66%, respectively, thereby enhancing the system’s efficiency and adaptability to novel environments.
Modern smart buildings and environments rely on sensory infrastructure to capture and process information about their inhabitants. However, it remains challenging to ensure that this infrastructure complies with privacy norms, preferences, and regulations; individuals occupying smart environments are often occupied with their tasks, lack awareness of the surrounding sensing mechanisms, and are non-technical experts. This problem is only exacerbated by the increasing number of sensors being deployed in these environments, as well as services seeking to use their sensory data. As a result, individuals face an unmanageable number of privacy decisions, preventing them from effectively behaving as their own "privacy firewall" for filtering and managing the multitude of personal information flows. These decisions often require qualitative reasoning over privacy regulations, understanding privacy-sensitive contexts, and applying various privacy transformations when necessary. We propose the use of Large Language Models (LLMs), which have demonstrated qualitative reasoning over social/legal norms, sensory data, and program synthesis, all of which are necessary for privacy firewalls. We present PrivacyOracle, a prototype system for configuring privacy firewalls on behalf of users using LLMs, enabling automated privacy decisions in smart built environments. Our evaluation shows that PrivacyOracle achieves up to 98% accuracy in identifying privacy-sensitive states from sensor data, and demonstrates 75% accuracy in measuring social acceptability of information flows.
Safety-critical Industrial Control Systems (ICS) are increasingly targeted by Advanced Persistent Threats (APTs), exemplified by attacks like Stuxnet, the Ukraine power grid breaches, and recent U.S. water treatment facility intrusions. These sophisticated attacks often target common sensors and actuator abstractions across different ICS environments. While frameworks like MITRE ATT&CK for ICS categorize attacker Tactics, Techniques, and Procedures (TTPs), they fall short in assessing the physical impact on operational technology (OT). To bridge this gap, we introduce OTThreat, a novel ontology that extends the Semantic Sensor Network (SSN) framework by incorporating cyber attack abstractions and the safety properties they target. Our approach enables the mapping of similar physical processes across different ICS domains, facilitating the adaptation of existing mitigations to new threats. We implement and validate a proof-of-concept threat inference framework on three ICS use cases representing different physical domains, including water treatment ICS and oil treatment ICS, that share common sensor and actuator abstractions and demonstrate how both threat assessment and potential mitigations for discovered threats can be adapted across physical domains.
Long-term and fine-grained maritime localization and sensing is challenging due to sporadic connectivity, constrained power budget, limited footprint, and hostile environment. In this paper, we present the design considerations and implementation of LocoMote , a rugged ultra-low-footprint undersea sensor tag with on-device AI-driven localization, online communication, and energy-harvesting capabilities. LocoMote uses on-chip (< 30 kB) neural networks to track underwater objects within 3 meters with ~6 minutes of GPS outage from 9DoF inertial sensor readings. The tag streams data at 2-5 kbps (< 10 -3 bit error rate) using piezo-acoustic ultrasonics, achieving underwater communication range of more than 50 meters while allowing up to 55 nodes to concurrently stream via randomized time-division multiple access. To recharge the battery during sleep, the tag uses an aluminum-air salt water energy harvesting system, generating upto 5 mW of power. LocoMote is ultra-lightweight (< 50 grams), tiny (32×32×10 mm 3 ), consumes low power (~330 mW peak), and comes with a suite of high-resolution sensors. We highlight the hardware and software design decisions, implementation lessons, and the real-world performance of our tag versus existing oceanic sensing technologies.
In this inaugural workshop, our goal for HealthSec'24 is to encourage, jumpstart, grow, and support an interdisciplinary community of researchers focused on cybersecurity in healthcare. This is the first cybersecurity research forum of any kind to have participation from credentialed medical doctors with backgrounds and/or responsibilities related to cybersecurity in healthcare.
Vegetation seasonality is a critical indicator of ecological responses to global climate change, especially in the Iberian Peninsula, where the intersection of human activity and climate variability amplifies these effects. Understanding these changes is vital for adopting ecogeographical sustainability and developing effective climate adaptation strategies. This study examines trends in vegetation seasonality in the Iberian Peninsula from 1982 to 2023, based on weekly AVHRR NDVI data (2184 images). By integrating Seasonal Trend Analysis (STA) with Robust Trend Analysis (RTA)—including the Theil–Sen (TS) slope estimator, the Contextual Mann–Kendall (CMK) test (α = 0.05), and false discovery rate (FDR) control—we identified significant phenological shifts and widespread vegetation greening. The results reveal a regional response to global patterns of climate change, with 94.2% of the study area exhibiting significant trends, particularly in the Mediterranean ecoregion, where earlier growing seasons are becoming increasingly common. These shifts highlight the urgent need for sustainable land and resource management in the face of accelerating global change. Our findings provide critical insights into the ecological dynamics of the Iberian Peninsula, offering a robust foundation for formulating policies that promote environmental sustainability and enhance resilience to climate change.
In spatiotemporal trend analysis, selective inference occurs when researchers are only interested in significant trends based on a fixed threshold (α, often 0.05), without considering the total number of statistical tests performed. Using simultaneous inference in gridded data involves thousands of trend tests, one for each pixel, leading to multiple testing or multiplicity problems. Multiplicity increases the chance of false discoveries in an unknown way unless the p-values of all tests performed are appropriately considered and adjusted.This discussion paper provides a selective and non-exhaustive review of the problems of multiplicity and selective inference. We discuss some appropriate methods to cope with the inflation of spurious results and comment on some examples based on gridded data in the context of research on spatiotemporal trend analysis. In addition, we suggest some good practices in transparency to facilitate the replicability of studies.The effects of uncorrected multiplicity and selective interference can be likened to a ghostly layer over the data, projecting illusions of significance that vanish with rigorous correction methods, revealing the true statistical skeleton of the results. The basis for addressing these problems is to assume that, although it may sometimes seem counterintuitive, the reality of what we perceive as statistically significant (i.e., p-values <0.05) also depends on the number (and value) of what we perceive as non-significant (i.e., p-values ≥0.05). Indeed, in a multiplicity context, one cannot correctly decide what is statistically significant until the whole story is known. Uncorrected selective inference precisely involves ignoring part of the story.
To transform cybersecurity and privacy research into a highly integrated, community-wide effort, researchers need a common, rich, representative research infrastructure that meets the needs across all members of the research community and facilitates reproducible science. USC Information Sciences Institute and Northeastern University are meeting researcher needs and have been funded by the NSF mid-scale research infrastructure program to build Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE). SPHERE research infrastructure will offer access to an unprecedented variety of user-configurable hardware, software, and network resources, it will offer six user portals geared toward different populations of users, and it will support reproducible research via a combination of infrastructure services and community engagement activities.
We introduce a novel methodological framework for robust trend analysis (RTA) using remote sensing data to enhance the accuracy and reliability of detecting significant environmental trends. Our approach sequentially integrates the Theil–Sen (TS) slope estimator, the Contextual Mann–Kendall (CMK) test, and the false discovery rate (FDR) control. This comprehensive method addresses common challenges in trend analysis, such as handling small, noisy datasets with outliers and issues related to spatial autocorrelation, cross-correlation, and multiple testing. We applied this RTA workflow to study tree cover trends in Los Alcornocales Natural Park (Southern Spain), Europe’s largest cork oak forest, analysing interannual changes in tree cover from 2000 to 2022 using Terra MODIS MOD44B data. Our results reveal that the TS estimator provides a robust measure of trend direction and magnitude, but its effectiveness is dramatically enhanced when combined with the CMK test. This combination highlights significant trends and effectively corrects for spatial autocorrelation and cross-correlation, ensuring that genuine environmental signals are distinguished from statistical noise. Unlike previous workflows, our approach incorporates the FDR control, which successfully filtered out 29.6% of false discoveries in the case study, resulting in a more stringent assessment of true environmental trends captured by multi-temporal remotely sensed data. In the case study, we found that approximately one-third of the area exhibits significant and statistically robust declines in tree cover, with these declines being geographically clustered. Importantly, these trends correspond with relevant changes in tree cover, emphasising the ability of RTA to detect relevant environmental changes. Overall, our findings underscore the crucial importance of combining these methods, as their synergy is essential for accurately identifying and confirming robust environmental trends. The proposed RTA framework has significant implications for environmental monitoring, modelling, and management.
Advancements in tracking algorithms have empowered nascent applications across various domains, from steering autonomous vehicles to guiding robots to enhancing augmented reality experiences for users. However, these algorithms are application-specific and do not work across applications with different types of motion; even a tracking algorithm designed for a given application does not work in scenarios deviating from highly standard conditions. For example, a tracking algorithm designed for robot navigation inside a building will not work for tracking the same robot in an outdoor environment. To demonstrate this problem, we evaluate the performance of the state-of-the-art tracking methods across various applications and scenarios. To inform our analysis, we first categorize algorithmic, environmental, and locomotion-related challenges faced by tracking algorithms. We quantitatively evaluate the performance using multiple tracking algorithms and representative datasets for a wide range of Internet of Things (IoT) and Extended Reality (XR) applications, including autonomous vehicles, drones, and humans. Our analysis shows that no tracking algorithm works across different applications and scenarios within applications. Ultimately, using the insights generated from our analysis, we discuss multiple approaches to improving the tracking performance using input data characterization, leveraging intermediate information, and output evaluation.
Inertial navigation provides a small footprint, low-power, and low-cost pathway for localization in GPS-denied environments on extremely resource-constrained Internet-of-Things (IoT) platforms. Traditionally, application-specific heuristics and physics-based kinematic models are used to mitigate the curse of drift in inertial odometry. These techniques, albeit lightweight, fail to handle domain shifts and environmental non-linearities. Recently, deep neural-inertial sequence learning has shown superior odometric resolution in capturing non-linear motion dynamics without human knowledge over heuristic-based methods. These AI-based techniques are data-hungry, suffer from excessive resource usage, and cannot guarantee following the underlying system physics. This paper highlights the unique methods, opportunities, and challenges in porting real-time AI-enhanced inertial navigation algorithms onto IoT platforms. First, we discuss how platform-aware neural architecture search coupled with ultra-lightweight model backbones can yield neural-inertial odometry models that are 31–134 x smaller yet achieve or exceed the localization resolution of state-of-the-art AI-enhanced techniques. The framework can generate models suitable for locating humans, animals, underwater sensors, aerial vehicles, and precision robots. Next, we showcase how techniques from neurosymbolic AI can yield physics-informed and interpretable neural-inertial navigation models. Afterward, we present opportunities for fine-tuning pre-trained odometry models in a new domain with as little as 1 minute of labeled data, while discussing inexpensive data collection and labeling techniques. Finally, we identify several open research challenges that demand careful consideration moving forward.
Safety-critical cyber-physical systems, such as autonomous vehicles and medical devices, are often driven by notions of state provided by sensor information translated through embedded firmware. This sensor pipeline is often a fragmented supply chain across vendors, and analyzing the associated security properties entails semantic reverse engineering of third-party software, i.e., mapping low-level software representations to cyber-physical models without access to source code. This mapping is a manual, time-consuming, and error-prone process. This paper introduces SensorLoader, a tool designed to automate mapping sensor semantics across all layers of closed-source software representations. SensorLoader exploits open-source knowledge, potentially derived from structured vendor description files or unstructured vendor datasheets, to extract and infer sensor semantics. We leverage large language models to extract sensor semantics from unstructured sources and map the semantics to memory maps and structures used by the Ghidra reverse engineering framework. We formalize the limitations of this automatic extraction and demonstrate how our approach can streamline the reverse engineering process for embedded systems. Preliminary evaluations suggest that SensorLoader can effectively and scalably aid in identifying vulnerabilities and deviations from expected behaviors, offering a more efficient pathway to secure cyber-physical systems.
Existing approaches for autonomous control of pan-tilt-zoom (PTZ) cameras use multiple stages where object detection and localization are performed separately from the control of the PTZ mechanisms. These approaches require manual labels and suffer from performance bottlenecks due to error propagation across the multi-stage flow of information. The large size of object detection neural networks also makes prior solutions infeasible for real-time deployment in resource-constrained devices. We present an end-to-end deep reinforcement learning (RL) solution called Eagle1 to train a neural network policy that directly takes images as input to control the PTZ camera. Training reinforcement learning is cumbersome in the real world due to labeling effort, runtime environment stochasticity, and fragile experimental setups. We introduce a photo-realistic simulation framework for training and evaluation of PTZ camera control policies. Eagle achieves superior camera control performance by maintaining the object of interest close to the center of captured images at high resolution and has up to 17% more tracking duration than the state-of-the-art. Eagle policies are lightweight (90x fewer parameters than Yolo5s) and can run on embedded camera platforms such as Raspberry PI (33 FPS) and Jetson Nano (38 FPS), facilitating real-time PTZ tracking for resource-constrained environments. With domain randomization, Eagle policies trained in our simulator can be transferred directly to real-world scenarios2.
IoT applications of increasing complexity for many applications require in-network processing of data from many sources, leveraging hybrid edge and cloud computing resources. In battlefield and defence settings, IoT applications also demand dependable operations, guaranteeing security and resource availability. It is challenging to orchestrate distributed computing for these applications, identifying the optimal placement of computing tasks in the face of dynamics in resource availability and network conditions. It becomes even more challenging to enable distributed computing in an adversarial environment where the data being processed as well as meta-data about resource availability could be manipulated, and the computing and networking resources may be compromised. Therefore, it is essential to develop frameworks to orchestrate distributed computing challenges in battlefield IoT networks. We survey the challenges and the existing state of the art, present some solutions, and identify key directions for future work.
End-to-end deep learning models are increasingly applied to safety-critical human activity recognition (HAR) applications, e.g., healthcare monitoring and smart home control, to reduce developer burden and increase the performance and robustness of prediction models. However, integrating HAR models in safety-critical applications requires trust, and recent approaches have aimed to balance the performance of deep learning models with explainable decision-making for complex activity recognition. Prior works have exploited the compositionality of complex HAR (i.e., higher-level activities composed of lower-level activities) to form models with symbolic interfaces, such as concept-bottleneck architectures, that facilitate inherently interpretable models. However, feature engineering for symbolic concepts-as well as the relationship between the concepts-requires precise annotation of lower-level activities by domain experts, usually with fixed time windows, all of which induce a heavy and error-prone workload on the domain expert. In this paper, we introduce X-CHAR , an eXplainable Complex Human Activity Recognition model that doesn't require precise annotation of low-level activities, offers explanations in the form of human-understandable, high-level concepts, while maintaining the robust performance of end-to-end deep learning models for time series data. X-CHAR learns to model complex activity recognition in the form of a sequence of concepts. For each classification, X-CHAR outputs a sequence of concepts and a counterfactual example as the explanation. We show that the sequence information of the concepts can be modeled using Connectionist Temporal Classification (CTC) loss without having accurate start and end times of low-level annotations in the training dataset-significantly reducing developer burden. We evaluate our model on several complex activity datasets and demonstrate that our model offers explanations without compromising the prediction accuracy in comparison to baseline models. Finally, we conducted a mechanical Turk study to show that the explanations provided by our model are more understandable than the explanations from existing methods for complex activity recognition.